CVE-2021-1583: Cisco Nexus 9000 Series Fabric Switches ACI Mode Arbitrary File Read Vulnerability
A vulnerability in the fabric infrastructure file system access control of Cisco Nexus 9000 Series Fabric Switches in Application Centric Infrastructure (ACI) mode could allow an authenticated, local attacker to read arbitrary files on an affected system. This vulnerability is due to improper access control. An attacker with Administrator privileges could exploit this vulnerability by executing a specific vulnerable command on an affected device. A successful exploit could allow the attacker to read arbitrary files on the file system of the affected device.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2021-1583?
CVE-2021-1583 is a vulnerability in the fabric infrastructure file system access control of Cisco Nexus 9000 Series Fabric Switches in Application Centric Infrastructure (ACI) mode.
How does CVE-2021-1583 affect Cisco Nexus 9000 Series Fabric Switches?
CVE-2021-1583 could allow an authenticated, local attacker to read arbitrary files on an affected system.
What is the severity of CVE-2021-1583?
The severity of CVE-2021-1583 is medium with a CVSS score of 4.4.
How can I fix CVE-2021-1583?
To fix CVE-2021-1583, it is recommended to apply the necessary updates or patches provided by Cisco.
Where can I find more information about CVE-2021-1583?
You can find more information about CVE-2021-1583 on the Cisco Security Advisory website.